CSS exploit in Chrome: how CVE-2026-2441 actually works
Ahmad Wael explains CVE-2026-2441, a Use-After-Free bug in Chrome’s Blink CSS engine triggered through @font-feature-values. It’s not literal code execution via CSS, but it’s a real reason to update your browser now.